Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2014-03-18 CVE-2014-2536 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown vectors.
network
intel mcafee CWE-22
4.3
2014-03-18 CVE-2014-2535 Path Traversal vulnerability in Mcafee web Gateway 7.2.0.9/7.3.2.4/7.4.0
Directory traversal vulnerability in McAfee Web Gateway (MWG) 7.4.x before 7.4.1, 7.3.x before 7.3.2.6, and 7.2.0.9 and earlier allows remote authenticated users to read arbitrary files via a crafted request to the web filtering port.
network
low complexity
mcafee CWE-22
4.0
2014-03-18 CVE-2013-2641 Path Traversal vulnerability in Sophos web Appliance and web Appliance Firmware
Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.
network
low complexity
sophos CWE-22
5.0
2014-03-18 CVE-2013-2619 Path Traversal vulnerability in Aspen 0.8
Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a ..
network
low complexity
aspen CWE-22
5.0
2014-03-18 CVE-2012-5641 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the default URI.
network
low complexity
apache mochiweb-project CWE-22
5.0
2014-03-18 CVE-2014-1975 Path Traversal vulnerability in R-Company Unzipper 1.0.0/1.0.1
Directory traversal vulnerability in the R-Company Unzipper application 1.0.1 and earlier for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename.
network
r-company CWE-22
5.8
2014-03-14 CVE-2013-2085 Path Traversal vulnerability in Owncloud
Directory traversal vulnerability in apps/files_trashbin/index.php in ownCloud Server before 5.0.6 allows remote authenticated users to access arbitrary files via a ..
network
low complexity
owncloud CWE-22
4.0
2014-03-14 CVE-2013-2039 Path Traversal vulnerability in Owncloud
Directory traversal vulnerability in lib/files/view.php in ownCloud before 4.0.15, 4.5.x 4.5.11, and 5.x before 5.0.6 allows remote authenticated users to access arbitrary files via unspecified vectors.
network
low complexity
owncloud CWE-22
4.0
2014-03-14 CVE-2014-2324 Path Traversal vulnerability in multiple products
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a ..
network
low complexity
lighttpd debian opensuse suse contec CWE-22
5.0
2014-03-11 CVE-2013-5639 Path Traversal vulnerability in Raoul Proenca Gnew 2013.1
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrary files via a ..
network
low complexity
raoul-proenca CWE-22
7.5